CVE-2023-41798

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Nov 7, 2023
Updated: Nov 14, 2023
CWE ID 1236

Summary

CVE-2023-41798 is a vulnerability affecting the Directorist – WordPress Business Directory Plugin with Classified Ads Listings, specifically an Improper Neutralization of Formula Elements in a CSV File. This issue puts versions from n/a to 7.7.1 at risk. An attacker could exploit this vulnerability by injecting malicious formulas into CSV files, potentially leading to arbitrary code execution and security breaches. Users are strongly advised to update their plugin to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share